Path Traversal in Satel Iberia SenNet Datalogger Serie 200

Posted date 07/10/2026
Identificador
INCIBE-2026-714
Importance
4 - High
Affected Resources

SenNet Datalogger Serie 200 V7.0m-1.53h.

Description

INCIBE has coordinated the publication of a high severity vulnerability affecting SenNet Datalogger Serie 200 by Satel Iberia, hardware for monitoring and controlling commercial and industrial buildings. The vulnerability was discovered by rijndael86.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-5703: CVSS v4.0: 7.1 | CVSS AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-35
Solution

The vulnerability has been fixed by Satel Iberia team in version V7.2a.

Detail

CVE-2026-5703: Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-5703 Alta No SATEL IBERIA
References list